CVE-2025-9317

8.4

AVEVA · Edge

AVEVA Edge contains a vulnerability involving weak password hashing, which allows local attackers with read access to project or cache files to recover Active Directory or application credentials.

Executive summary

A critical credential exposure vulnerability in AVEVA Edge software permits unauthorized password recovery through brute-force attacks on weak hashes.

Vulnerability

This vulnerability, classified under CWE-327 (Use of a Broken or Risky Cryptographic Algorithm), involves the storage of credentials using insufficient hashing methods. An attacker with local read access to project files or offline cache files can perform computational brute-forcing to reverse engineer user passwords.

Business impact

Successful exploitation of this vulnerability poses a severe risk to organizational security by enabling unauthorized access to sensitive systems. Because the flaw allows for the recovery of Active Directory passwords, an attacker could potentially escalate privileges or move laterally within the network. With a CVSS score of 8.4, this vulnerability is considered High severity and requires immediate attention to prevent identity compromise and potential data breaches.

Remediation

Immediate Action: Update to AVEVA Edge 2023 R2 P01 and follow the vendor instructions to migrate existing project files to the new secure format.

Proactive Monitoring: Review file system access logs for unauthorized attempts to read Edge project or configuration files, particularly by non-administrative service accounts.

Compensating Controls: Implement strict file system permissions to limit access to the directory containing Edge project files to only the necessary service accounts.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The exposure of administrative or Active Directory credentials represents a significant security failure that could lead to a total compromise of the affected environment. Organizations must prioritize the migration of legacy project files to the patched version, as simply applying the update is insufficient without the recommended file migration. Apply the security update and perform the required project migration immediately to neutralize the risk of password recovery.

Sources

Originally found and disclosed by Joao Varelas reported this vulnerability to AVEVA., per the CVE Program record.